{"id":20876,"date":"2026-09-24T08:11:36","date_gmt":"2026-09-24T08:11:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20876"},"modified":"2026-09-24T08:11:36","modified_gmt":"2026-09-24T08:11:36","slug":"fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcp_fct_ad-7-4-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Fortinet FCP_FCT_AD-7.4 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/fcp-fct-ad-7-4-exam-dumps\"><b>Fortinet FCP_FCT_AD-7.4 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 221. Starting with EMS 7.4.5, what capability is available for protecting the EMS database without relying on an external cron job?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic database replication to every endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatic export to FortiAnalyzer only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Scheduled EMS database backups configured directly in EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continuous database backup to FortiGate flash storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Scheduled EMS database backups configured directly in EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Starting with EMS 7.4.5, administrators can configure scheduled database backups directly under <\/span><b>System Settings &gt; EMS Settings &gt; Scheduled Backup<\/b><span style=\"font-weight: 400;\">. Fortinet recommends using this built-in scheduled-backup functionality for automated EMS database protection. Administrators can determine how frequently backups occur and whether the resulting files are stored locally or sent to a supported remote server. Earlier environments could automate backups with operating-system tools such as cron jobs, but the integrated scheduling capability simplifies routine backup administration. Regular database backups are important because EMS contains endpoint-management configuration, policies, profiles, administrative data, and other critical management information.<\/span><\/p>\n<p><b>Question 222. Which schedule types are supported by the EMS 7.4.5 scheduled database backup feature?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Daily, weekly, and monthly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hourly only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Quarterly and yearly only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Every five minutes only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Daily, weekly, and monthly<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The built-in scheduled-backup feature supports <\/span><b>daily, weekly, and monthly<\/b><span style=\"font-weight: 400;\"> schedules. Administrators can define the interval appropriate to each schedule type. For example, a weekly schedule can specify how many weeks should pass between backups and which days of the week the backup should occur. EMS also allows the administrator to specify the starting time in UTC. The selected schedule should reflect the organization&#8217;s recovery objectives, rate of configuration change, available storage, and operational requirements. Frequent backups reduce the amount of recent EMS configuration that could be lost following a database failure.<\/span><\/p>\n<p><b>Question 223. Which remote protocols can EMS use to store scheduled database backups on an external server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP and HTTPS only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SMB and NFS only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FTP and TFTP only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SCP or SFTP**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. SCP or SFTP<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For built-in scheduled backups, EMS supports storing the backup on a remote server by using <\/span><b>SCP or SFTP<\/b><span style=\"font-weight: 400;\">. The administrator supplies information such as the remote server address, username, password, backup path, and other required connection settings. The account used for the backup must have permission to write to the selected remote location. Keeping backups on a separate system can improve recoverability because the backup remains available even if the EMS server itself becomes unavailable. Organizations should also protect remote credentials and backup files according to their security policies.<\/span><\/p>\n<p><b>Question 224. Which two backup output formats can an administrator select when manually backing up the EMS database from the System Information widget?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ISO or TAR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Database or Zip<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MSI or EXE<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CSV or XML<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Database or Zip<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When creating an EMS database backup from the <\/span><b>System Information<\/b><span style=\"font-weight: 400;\"> widget, the administrator can select <\/span><b>Database<\/b><span style=\"font-weight: 400;\"> or <\/span><b>Zip<\/b><span style=\"font-weight: 400;\"> as the compression type. The Database option produces the EMS database backup format, while Zip packages the backup as a compressed archive. The administrator also supplies and confirms a password, which is later required when restoring the database. Backups should be stored securely because they may contain sensitive management configuration and endpoint-related information. Administrators should also periodically validate their restore procedures instead of assuming that successful backup creation alone guarantees recoverability.<\/span><\/p>\n<p><b>Question 225. What credential is required when restoring an EMS database backup through the GUI?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The password that was assigned when the database backup was created<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiGate administrator password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The endpoint user&#8217;s Windows password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The EMS license registration code<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The password that was assigned when the database backup was created<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an EMS database backup is created, the administrator specifies a backup password. During restoration, EMS requires that same password before the database can be restored. This protects the backup and prevents unauthorized restoration of its contents. The restore workflow is available from the System Information widget, where the administrator selects the backup file, enters the original backup password, and starts restoration. After the database has been restored, EMS needs time to reload the restored information before normal administration resumes. The backup password is unrelated to FortiGate credentials or endpoint user passwords.<\/span><\/p>\n<p><b>Question 226. Beginning with EMS 7.4.4, which database-restore capability is supported?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restoring only between identical standalone servers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restoring only from HA to HA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restoring only from Linux to Windows EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restoring across deployment models, such as standalone EMS to EMS HA or vice versa**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Restoring across deployment models, such as standalone EMS to EMS HA or vice versa<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that starting with <\/span><b>EMS 7.4.4<\/b><span style=\"font-weight: 400;\">, database restoration can occur across different deployment models. For example, administrators can restore a backup from a standalone EMS into an EMS HA setup or restore from an HA environment into a standalone deployment. This is an improvement over earlier 7.4 behavior, where cross-model restoration had limitations. The capability provides greater flexibility for disaster recovery, architecture changes, and migration planning. Administrators should still use a supported version-specific restoration procedure and confirm database compatibility before making a production architecture change.<\/span><\/p>\n<p><b>Question 227. When using the EMS CLI <\/b><b>execute restore<\/b><b> command with a local backup file, where must the file be located according to the documented 7.4.4 CLI workflow?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">\/tmp<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">\/exchange<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">\/var\/www<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">\/home\/admin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. <\/b><b>\/exchange<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In the documented EMS 7.4.4 CLI restore workflow, a backup specified with the <\/span><span style=\"font-weight: 400;\">&#8211;local.file<\/span><span style=\"font-weight: 400;\"> option must be located in the <\/span><b>\/exchange<\/b><span style=\"font-weight: 400;\"> directory. The <\/span><span style=\"font-weight: 400;\">execute restore<\/span><span style=\"font-weight: 400;\"> command can restore backups from either local or remote locations. When restoring remotely, administrators provide the remote server information and select a supported copy service such as SCP, FTP, or SFTP. Knowing the required local path prevents restore attempts from failing because the backup file exists on the EMS server but is stored outside the location accepted by the command.<\/span><\/p>\n<p><b>Question 228. Which statement about deleting an endpoint from FortiClient EMS is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any registered domain endpoint can always be deleted directly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS deletes endpoints only after FortiGate approval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Delete Device option is available for disconnected non-domain devices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleting an endpoint automatically uninstalls FortiClient from every device<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The Delete Device option is available for disconnected non-domain devices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet documents that administrators can delete <\/span><b>disconnected non-domain devices<\/b><span style=\"font-weight: 400;\"> from EMS. If the endpoint is still registered, the administrator should disconnect it first and then use <\/span><b>Action &gt; Delete Device<\/b><span style=\"font-weight: 400;\">. The deletion option is not a general mechanism for removing every domain-managed endpoint from directory-based management, nor does deleting the EMS record automatically uninstall FortiClient software from the operating system. Administrators should distinguish between deleting an EMS record, deregistering an endpoint, uninstalling FortiClient, and removing a device from a directory environment because each operation has a different purpose.<\/span><\/p>\n<p><b>Question 229. An administrator selects \u201cDeregister\u201d for an online FortiClient endpoint in EMS. When does EMS perform the disconnection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> At the endpoint&#8217;s next FortiClient Telemetry communication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after EMS reboots<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exactly 24 hours later<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after FortiAnalyzer confirms the request<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. At the endpoint&#8217;s next FortiClient Telemetry communication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an administrator chooses <\/span><b>Deregister<\/b><span style=\"font-weight: 400;\">, EMS disconnects the endpoint during the endpoint&#8217;s next FortiClient Telemetry communication. This behavior is similar to other EMS remote actions that depend on the endpoint communicating with its management server. After deregistration, FortiClient can later be manually reconnected to EMS if appropriate. Deregistration should not be confused with network quarantine or deleting the endpoint record. Quarantine restricts network access, while deregistration terminates the FortiClient-to-EMS management relationship. If an endpoint is offline, the deregistration command cannot reach the device until management communication resumes.<\/span><\/p>\n<p><b>Question 230. Which EMS endpoint action requests FortiClient log files from a managed device for troubleshooting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Clear Events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Request FortiClient Logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Set Importance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mark as Uninstalled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Request FortiClient Logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The EMS Endpoints pane includes <\/span><b>Request FortiClient Logs<\/b><span style=\"font-weight: 400;\"> as a remote action. This allows administrators to obtain FortiClient-generated logs from a managed endpoint for troubleshooting. EMS also provides separate actions for requesting diagnostic results and downloading available logs or diagnostic packages. These capabilities are useful when investigating endpoint-specific problems such as policy application, VPN behavior, Web Filter issues, or communication errors. Administrators should select the action that corresponds to the information they need rather than assuming normal EMS server logs contain all endpoint-level diagnostic data.<\/span><\/p>\n<p><b>Question 231. Which EMS endpoint action is designed to obtain a broader diagnostic package rather than ordinary FortiClient log files?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Set Custom Tags<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Update Signatures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Request Diagnostic Results<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Move To<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Request Diagnostic Results<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><b>Request Diagnostic Results<\/b><span style=\"font-weight: 400;\"> instructs a managed endpoint to generate a diagnostic package containing information useful for deeper FortiClient troubleshooting. This is separate from <\/span><b>Request FortiClient Logs<\/b><span style=\"font-weight: 400;\">, which focuses on client logs. EMS also provides options to download available diagnostic results after they have been generated and uploaded. Diagnostic packages can provide broader system and FortiClient state information and are often useful when escalating a difficult issue to Fortinet support. Because these remote requests depend on endpoint communication, an offline endpoint may not immediately process the request.<\/span><\/p>\n<p><b>Question 232. What happens when an EMS administrator uses \u201cRevoke Client Certificate\u201d on a supported endpoint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS removes the endpoint&#8217;s Windows login certificate permanently with no replacement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiGate licensing is revoked<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the VPN password is cleared<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS revokes the FortiClient ZTNA certificate and prompts FortiOS and FortiClient to establish a new certificate signing request**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. EMS revokes the FortiClient ZTNA certificate and prompts FortiOS and FortiClient to establish a new certificate signing request<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Revoke Client Certificate<\/b><span style=\"font-weight: 400;\"> action is used when the ZTNA certificate held by FortiClient may be compromised or should no longer be trusted. Fortinet states that after revocation, EMS prompts FortiOS and FortiClient with a new certificate-signing request so a replacement trust relationship can be established. This action is available when the relevant ZTNA or EPP licensing is present. The certificate is used when FortiClient securely tunnels TCP application traffic through HTTPS to FortiGate in ZTNA workflows, so certificate integrity is essential to device trust.<\/span><\/p>\n<p><b>Question 233. What does the \u201cDelete Stale Verified Users\u201d endpoint action do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes all EMS administrator accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removes stale verified users while retaining the last-seen record for each machine user<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revokes every FortiClient license assigned to the device<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes the device from Active Directory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Removes stale verified users while retaining the last-seen record for each machine user<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Delete Stale Verified Users<\/b><span style=\"font-weight: 400;\"> action cleans up older verified-user records associated with an endpoint. Fortinet explains that EMS keeps the most recently seen record for each machine user while removing stale verified-user entries. For example, if multiple users have onboarded through FortiClient on the same endpoint, older records can be removed. Importantly, Fortinet notes that this operation <\/span><b>does not affect license seats<\/b><span style=\"font-weight: 400;\">. It is therefore an identity-record maintenance operation rather than a licensing or directory-account deletion function.<\/span><\/p>\n<p><b>Question 234. What is the primary purpose of the FortiClient EMS REST API?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To perform configuration operations on EMS programmatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace FortiClient antivirus signatures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide IPsec encryption between endpoints<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To configure only the PostgreSQL database<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To perform configuration operations on EMS programmatically<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The FortiClient EMS API allows administrators and integrations to perform EMS configuration operations programmatically rather than relying exclusively on the graphical interface. Fortinet provides API documentation through the <\/span><b>FortiAPI<\/b><span style=\"font-weight: 400;\"> section of the Fortinet Developer Network. API access can support automation, integration with external systems, and repeatable administrative workflows. It should be protected with appropriate authentication and least-privilege controls because programmatic configuration access can affect managed endpoints and EMS settings. The API complements rather than replaces FortiClient Telemetry, which is the endpoint-management communication channel between FortiClient and EMS.<\/span><\/p>\n<p><b>Question 235. Where does Fortinet direct administrators to view detailed FortiClient EMS API documentation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiGate routing monitor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The Microsoft Entra portal<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiAPI tab on the Fortinet Developer Network<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiClient endpoint log viewer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The FortiAPI tab on the Fortinet Developer Network<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet&#8217;s EMS documentation states that detailed API information is available through the <\/span><b>FortiAPI tab on FNDN<\/b><span style=\"font-weight: 400;\">, the Fortinet Developer Network. The EMS Administration Guide confirms that the REST API can perform configuration operations but refers administrators to FNDN for the detailed interface documentation. This separation allows Fortinet to maintain developer-oriented specifications independently of the general administration guide. Administrators planning automation should use the current API documentation that matches the EMS version they operate and should test programmatic changes in a controlled environment before applying them to production.<\/span><\/p>\n<p><b>Question 236. When can an administrator manually renew an ACME certificate from the EMS Server Certificates page?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only after the certificate has been expired for 90 days<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> When the ACME certificate is within 30 days of expiration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only when every endpoint is offline<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only during EMS license renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. When the ACME certificate is within 30 days of expiration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiClient EMS supports ACME-managed server certificates, including certificates from services such as Let&#8217;s Encrypt. Fortinet states that when an ACME certificate becomes eligible for renewal\u2014specifically, when it is <\/span><b>within 30 days of expiration<\/b><span style=\"font-weight: 400;\">\u2014the administrator can select it on the EMS Server Certificates page and initiate renewal. Timely certificate renewal prevents HTTPS, installer-download, Telemetry, or other EMS services from presenting an expired certificate. ACME is designed to simplify certificate lifecycle management, but administrators should still monitor certificate status and verify that required ACME network connectivity remains available.<\/span><\/p>\n<p><b>Question 237. Which EMS service normally uses the configured endpoint-control certificate on TCP 8013?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> FortiClient endpoint-control\/Telemetry service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Chromebook profile service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Installer download service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EMS administrative GUI<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. FortiClient endpoint-control\/Telemetry service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fortinet maps the EMS <\/span><b>Endpoint Control daemon<\/b><span style=\"font-weight: 400;\"> to TCP <\/span><b>8013<\/b><span style=\"font-weight: 400;\">, the default port used for FortiClient endpoint management and Telemetry. EMS allows administrators to configure the certificate used by this service. Other EMS services use different ports and may use different certificate selections: the administrative web GUI commonly uses TCP 443, installer downloads use TCP 10443, FortiOS websocket notifications use TCP 8015, and the Chromebook profile service uses TCP 8443. Understanding which certificate protects each EMS service is useful when certificate trust problems affect only one component.<\/span><\/p>\n<p><b>Question 238. Which System Settings option permits a Windows user with appropriate administrative privileges to shut down FortiClient while it is registered to EMS?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hide System Tray Icon<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Do Not Allow User to Back Up Configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Show Host Tag on FortiClient GUI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow User to Shutdown When Registered to EMS**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Allow User to Shutdown When Registered to EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><b>Allow User to Shutdown When Registered to EMS<\/b><span style=\"font-weight: 400;\"> option controls whether a user can shut down FortiClient while the client remains registered with EMS. Fortinet specifies that this feature is available for FortiClient Windows and that the user must have administrative privileges to perform the shutdown. In a tightly controlled enterprise environment, administrators may prefer to prevent users from stopping FortiClient because doing so could temporarily interrupt endpoint-security enforcement. The setting should therefore reflect the organization&#8217;s balance between local administrative flexibility and continuous endpoint protection.<\/span><\/p>\n<p><b>Question 239. What does the \u201cHide System Tray Icon\u201d setting do on a managed FortiClient endpoint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables FortiClient Telemetry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes FortiClient from the endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hides the FortiClient icon from the operating system&#8217;s system tray<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevents EMS administrators from seeing the endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Hides the FortiClient icon from the operating system&#8217;s system tray<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><b>Hide System Tray Icon<\/b><span style=\"font-weight: 400;\"> is a FortiClient System Settings option that removes the FortiClient tray icon from the endpoint user&#8217;s normal desktop interface. This can reduce user interaction with FortiClient in managed environments where endpoint configuration is centrally controlled. Hiding the icon does not uninstall FortiClient, disable Telemetry, or remove the endpoint from EMS management. Administrators should distinguish interface-visibility controls from actual service or security-feature controls. FortiClient can continue enforcing its assigned EMS profiles while its tray icon is hidden from the user.<\/span><\/p>\n<p><b>Question 240. An organization wants recoverable EMS configuration, automated administration, protected ZTNA certificate handling, and clean removal of a retired non-domain endpoint. Which approach BEST meets these requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configure scheduled EMS database backups, use the EMS REST API with appropriate controls, revoke compromised client certificates when required, deregister a retired endpoint, and delete the disconnected non-domain device from EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Depend only on endpoint-local configuration backups and never back up EMS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete endpoints while they are registered and reuse compromised certificates<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all EMS certificates before using API automation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Configure scheduled EMS database backups, use the EMS REST API with appropriate controls, revoke compromised client certificates when required, deregister a retired endpoint, and delete the disconnected non-domain device from EMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The scenario combines several different EMS operational responsibilities. Scheduled database backups protect critical EMS configuration and simplify recovery. The EMS REST API supports controlled automation of configuration operations. ZTNA client certificates should be revoked when they are compromised so FortiClient and FortiOS can establish replacement certificate trust. Finally, a retired non-domain endpoint that is still registered should first be deregistered; once disconnected, its device record can be deleted from EMS. Treating backup, automation, certificate security, and endpoint lifecycle as separate but coordinated tasks provides a more reliable and secure management design.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCP_FCT_AD-7.4 Exam Dumps and Practice Test Dumps. Question 221. Starting with EMS 7.4.5, what capability is available for protecting the EMS database without relying on an external cron job? Automatic database replication to every endpoint Automatic export to FortiAnalyzer only Scheduled EMS database backups configured directly in EMS Continuous database backup to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20876"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20876"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20876\/revisions"}],"predecessor-version":[{"id":20877,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20876\/revisions\/20877"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}